We know it’s still hard for some of you to accept, but Microsoft really does support Linux — especially lately. One specific example: In June, Microsoft released Microsoft Defender Advanced Threat Protection (ATP) for Linux to all users. Now, Microsoft has improved the Linux version of Defender, adding a public preview of endpoint detection and response (EDR) capabilities.

This is not a version of Microsoft Defender that you can run on a standalone Linux desktop. Its main job remains to protect Linux servers from server and network. If you want protection for your standalone desktop, use programs like ClamAV or Sophos Antivirus for Linux.
For businesses, however, who have employees working from home and now use Macs and Windows computers everywhere, that's another story. While it's based on Linux servers, you'll be able to use it to protect computers running macOS, Windows 8.1 , and Windows 10.
With these new EDR capabilities, Linux Defender users can quickly detect advanced attacks involving Linux servers and remediate any threats. This builds on existing proactive antivirus capabilities and aggregated reporting available through the Microsoft Security Defender Center.
Specifically, it includes:
- Rich research, including “machine timeline”, process creation, file creation, network connections and connection events.
- Optimized CPU performance with improved performance in compilation processes and “large” software applications.
- In-context AV detection. As with the Windows version, you'll get information about where a threat came from and how the malicious process or activity was created.
To run the updated program, you will need one of the following Linux servers: RHEL 7.2+, CentOS Linux 7.2+, Ubuntu 16.04 or later LTS, SLES 12+, or Oracle Linux 7.2.
Then, to try these public preview features, you'll need to enable preview features in Microsoft Defender Security Center. Before you do this, make sure you're running version 101.12.99 or later. You can find out which version you're running with the command: mdatp health
You should not switch all servers running Microsoft Defender for Endpoint on Linux to preview mode. Instead, Microsoft recommends that you configure only some of your Linux servers to preview mode, with the following command: $ sudo mdatp edr early-preview enable

Once that's done, if you're feeling brave enough and want to see for yourself if it works, Microsoft offers a way to run a simulated attack. To do this, follow the steps below to simulate a probe on your Linux server and investigate the case.
1. Make sure the embedded Linux server appears in Microsoft Defender Security Center.
2.Download and extract the script file from here aka.ms/LinuxDIY to an embedded Linux server and run the following command: ./mde_linux_edr_diy.sh
3.After a few minutes, it should “open” in Microsoft Defender Security Center.
4. Look at the notification details, the so-called machine timeline, and perform your standard investigation steps.
Source: zdnet.com
